BambooToken malware controls Windows and Linux systems via MQTT
6 Articles
6 Articles
BambooToken malware controls Windows and Linux systems via MQTT
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems.
BambooToken shifts C2 traffic to MQTT across Windows and Linux
BambooToken, active since at least 2023, uses MQTT-based command and control in variants seen from 2024 to 2025, with Windows and Linux samples documented by Black Lotus Labs. Observed intrusions hit enterprise entities in Asia and South America, with...
Find out how BambooToken malware uses the MQTT protocol to infect Linux and Windows systems, mock firewalls and compromise sensitive servers.
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.
Coverage Details
Bias Distribution
- 50% of the sources are Center, 50% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium








